fix: validate Azure delegation key coverage - #867
Open
RanaPriyansh wants to merge 1 commit into
Open
RanaPriyansh wants to merge 1 commit into
RanaPriyansh wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Azure can grant a user delegation key whose validity does not cover a requested signed URL. The fixed cache window can also fetch another key while a cached key still covers the signed URL.
This change makes the requested key validity configurable, with a 12-hour default. A longer signed URL extends the key request. The cache reuses a key only when Azure's returned SignedStart and SignedExpiry cover the serialized SAS interval. It rejects an invalid granted interval before caching the key.
Addresses #807.
Validation
cargo test --features azure --lib— 175 passed, four ignored.cargo clippy --features azure -- -D warningscargo clippy --no-default-features --features azure-base -- -D warningscargo clippy --all-features --all-targets -- -D warningscargo fmt --all -- --checkgit diff --checkMock Azure responses test public signed URLs, cache reuse, refresh, concurrent signers, failed and canceled refresh, granted intervals, and the seven-day limit. The public tests compare SAS timestamps with the granted key interval and reject an insufficient grant. No live Azure account was used.
Codex used.